Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105796— Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators

Quick assessment

Affected
microsoft kiota
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kiota 是一个基于 OpenAPI 的 HTTP 客户端代码生成器。在版本 0.5.0 至 1.35.0 期间,Kiota 的 Java 和 PHP 文档注释清理器在清理过程中删除了块注释终止符(如 ),而不是将其转义或中性化处理,从而导致重叠字符可以重新组合形成新的注释终止符,使攻击者控制的 OpenAPI 文本得以跳出生成的文档注释范围。此外,Java 版本的清理器在删除终止符后还会移除非 ASCII 字符,这在字符归一化过程中可能意外生成新的注释终止符。要利用此漏洞,开发者或构建流水线需从恶意描述文件中生

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105796

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
Source: CVE Program / CVE List V5
Vulnerability Description
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
microsoft kiota >= 0.5.0, < 1.35.0 -
microsoft Microsoft.OpenApi.Kiota >= 0.5.0, < 1.35.0 -
microsoft Microsoft.OpenApi.Kiota.Builder >= 0.5.0, < 1.35.0 -

II. Public POCs for CVE-2026-105796

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105796

请登录查看更多情报信息。

Other References for CVE-2026-105796 (4)

Same Patch Batch · microsoft · 2026-10-06 · 11 CVEs total

CVE-2026-105794 9.1 CRITICAL MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
CVE-2026-105793 9.1 CRITICAL Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key`
CVE-2026-105797 8.8 HIGH SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spaw
CVE-2026-105788 8.8 HIGH Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and l
CVE-2026-105798 8.7 HIGH SimpleChat: Stored XSS via group document filename in inline onclick handler
CVE-2026-105791 7.5 HIGH Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injecti
CVE-2026-105792 6.5 MEDIUM Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager
CVE-2026-105790 6.4 MEDIUM Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinni
CVE-2026-105789 5.4 MEDIUM Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool
CVE-2026-105795 3.1 LOW Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests

IV. Related Vulnerabilities

V. Comments for CVE-2026-105796

No comments yet


Leave a comment